Anthropic is now running its Claude Security vulnerability scanning tool on Claude Mythos 5, the frontier cyber-defense model previously limited to vetted defenders in Project Glasswing. Claude Security is available in public beta for all Claude Enterprise customers today, with no separate model add-on—scans bill as standard token usage ($10 per million input tokens, $50 per million output tokens). The scans connect to GitHub repositories, trace data flows across files, and return findings with CWE categories, confidence/severity ratings, and suggested patches.
Critically, users do not get direct access to Mythos 5. Instead, they receive scan results and vulnerability findings; patches open in Claude Code on the web using the organization's existing models, and every patch requires human review and approval. This interface boundary—where the model runs behind a narrowly defined task and returns only specific artifacts—is Anthropic's argument for safe expansion. The company is also working with cybersecurity vendors to integrate Mythos 5 into their products, and launched the Defender Advantage Fund (0xDAF) providing $35 million in credits for open-source vulnerability remediation, automation, and security initiatives against broad classes of attacks.
For practitioners: Mythos 5 in Claude Security expands enterprise access to frontier vulnerability discovery (previously discovered 27-year-old OpenBSD bugs, 16-year-old FFmpeg flaws) while maintaining scoped, non-interactive control. The risk shift: enterprises will see vastly more high-severity findings flowing downstream from open-source libraries. Triage, prioritization, and operational governance around AI-discovered vulnerabilities become the new bottleneck.